Skip to main content
POST
POST /subscription enrolls a customer in a plan and establishes the recurring mandate that anchors every future Merchant Initiated Transaction (MIT). Enrolling a customer is a Cardholder Initiated Transaction (CIT), and a CIT may require 3D Secure. Two modes:

CIT mode — nonceData / cardData

Therius runs the initial CIT + first charge here. The customer must be present. This CIT cannot carry out a 3D Secure challenge — a 3DS-required card will fail.

Record mode — tokenData

The token is a card that already completed a CIT (including 3DS) through /payment/authorization or /payment/purchase. No second CIT runs here. Use this for any card that needs 3D Secure.
Supply the card as exactly one instrument — nonceData, cardData (PCI DSS compliant servers only), or tokenData.
cardOnFile and instalments are ignored here — Therius owns the mandate. In record mode networkTransactionId / networkReferenceId are read from the token; pass them only for a card CIT’d outside Therius.

Record mode

Run a 3DS-capable CIT yourself, then attach the result:
1

Run the CIT via /payment/*

Call /payment/authorization (amount 0 = account verification) or /payment/purchase with card.<x>.tokenize: true + a shopper.id, and handle any 3DS challenge with the JS SDK as you would for a normal payment. The response returns a vt_... token.
2

Create the subscription

POST /subscription with card.tokenData.token. For cycle 1:
• trial or deferred startAt → nothing is charged;
• you charged the first cycle in your CIT (/payment/purchase) → also pass firstPaymentId (the payment id from that call’s response); Therius marks the first invoice paid and links it, no charge;
• your CIT was a zero-value verification → omit firstPaymentId; Therius charges cycle 1 as an MIT against the recorded mandate (rolls the subscription back with a 402 if it declines).
The response’s firstCycle object reports what happened.
See the parameters panel above for the full field list — planId, customerEmail, and a card instrument (nonceData/cardData/tokenData — exactly one) are required; customerName/customerDocument, firstPaymentId (record mode), startAt, parentSubscriptionId/propagateLifecycle, and metadata are optional.

Response

A successful request returns 201 Created with the full subscription object, including the subscription id, initial status, current period start and end dates, and the first invoice.

Status on creation

Errors

Authorizations

Authorization
string
header
required

Your secret API key: Bearer prv_production_xxx (production) or Bearer prv_sandbox_xxx (sandbox).

Body

application/json
merchantCode
string
required

Your merchant account identifier.

planId
integer
required

ID of an active plan. Determines amount, currency, interval and trial.

customerEmail
string
required

Subscriber email. Used for billing and dunning notifications.

card
Raw card (PCI DSS) · object
required

Card input for creating a subscription. Enrolling a customer is a CIT and a CIT may require 3D Secure — pick the mode that fits:

CIT mode (nonceData / cardData): Therius runs the initial CIT + first charge here. The customer must be present. This CIT cannot carry out a 3D Secure challenge, so a 3DS-required card will fail — use record mode for those.

Record mode (tokenData): the token is a card that already completed a CIT — including any 3DS — through /payment/authorization or /payment/purchase (with card.<x>.tokenize: true + shopper.id). No second CIT runs. The mandate is read from the token; pass networkTransactionId / networkReferenceId explicitly only for a card CIT'd outside Therius. For cycle 1: with a trial or deferred start nothing is charged; with firstPaymentId set Therius marks the first invoice paid and links that payment; otherwise Therius charges cycle 1 as an MIT against the recorded mandate.

Provide exactly ONE of cardData, nonceData, or tokenData. cardOnFile and instalments are not accepted — Therius owns the mandate.

customerName
string

Subscriber full name, as it should appear on invoices.

customerDocument
string

Subscriber national ID / tax document, where a market requires it (e.g. Brazil CPF/CNPJ).

firstPaymentId
string

Record mode only, when a first payment is due. The payment id from the /payment/authorization or /payment/purchase call in which you ran this card CIT - Therius verifies it charged the same vaulted token in the plan currency, then marks cycle 1 paid and links it (no charge). Omit and Therius charges cycle 1 as an MIT against the recorded mandate.

startAt
string

RFC 3339 future timestamp to defer the first charge. Omit to activate (or start the trial) immediately.

parentSubscriptionId
string

UUID of an existing subscription to attach this one to as a child (add-on hierarchies).

propagateLifecycle
boolean

When true, pause/cancel on parentSubscriptionId cascades to this subscription. Requires parentSubscriptionId.

metadata
object

Arbitrary string key/value pairs, echoed on subscription responses and webhooks.

Response

201 - application/json

Subscription created. Body is the Subscription plus firstInvoice, and firstCycle in record mode (what happened to cycle 1).

A customer enrollment in a plan. plan is embedded on single-subscription responses. Invoice/event history is not included here - use the invoice endpoints.

id
string

Subscription UUID.

merchantId
integer

The merchant account that owns the subscription.

planId
integer

ID of the plan this subscription is enrolled in.

customerEmail
string

Subscriber email, used for billing and dunning notifications.

customerName
string

Subscriber name as it appears on invoices.

customerDocument
string

Subscriber national ID / tax document, where a market requires it (e.g. Brazil CPF/CNPJ).

cardBrand
string

Brand of the card on the mandate, e.g. visa.

status
enum<string>

pending - awaiting first charge; trialing - in a free trial; active - billing normally; past_due - a renewal failed and dunning is running; suspended - dunning exhausted, needs a new CIT (POST /subscription/{id}/payment-method in CIT mode) to recover; paused - billing stopped on request, resumable; cancelled - terminated; completed - reached maxBillingCycles.

Available options:
pending,
trialing,
active,
past_due,
suspended,
paused,
cancelled,
completed
currentPeriodStart
string<date-time>

Start of the current billing period.

currentPeriodEnd
string<date-time>

End of the current billing period.

nextBillingDate
string<date-time>

When the next renewal charge is scheduled.

trialStart
string<date-time>

Trial start, when the plan has a trial.

trialEnd
string<date-time>

Trial end - the first real charge date.

dunningAttemptCount
integer

Failed-renewal retry attempts made in the current dunning sequence.

activatedAt
string<date-time>

When the subscription first became active.

cancelledAt
string<date-time>
pausedAt
string<date-time>
suspendedAt
string<date-time>
startAt
string<date-time>

Deferred start, when creation set a future startAt.

cyclesCompleted
integer

Number of billing cycles charged so far.

completedAt
string<date-time>

When the subscription reached maxBillingCycles.

parentSubscriptionId
string

Parent subscription UUID, for add-on hierarchies.

propagateLifecycle
boolean

Whether pause/cancel on the parent cascades to this subscription.

pendingPlanId
integer

Plan the subscription will switch to at the next cycle, set by a next_billing change-plan.

createdAt
string<date-time>
updatedAt
string<date-time>
plan
object

A reusable billing plan. amount is a flat integer in the currency minor units (with separate currency + exponent) - not an Amount object.